Macksofy Technologies
Annual System Audit · CERT-In Empanelled

SEBI System Audit Report (SAR)

The half-yearly / annual SAR your stock broker or DP can submit on the first read.

Stock brokers and depository participants submit System Audit Reports to SEBI on a defined cycle. Macksofy delivers SARs that survive SEBI inspection because we draft them the way SEBI's auditors and inspection teams read them.

Aligned to
  • SEBI SAR Format (annexures)
  • SEBI CSCRF (2024)
  • SEBI Cybersecurity Circular 2015 (transition mapping)
  • Stock Exchange / Clearing Corp inspection format
  • CERT-In empanelment requirement
Why this matters

Compliance is leverage, not paperwork.

Brokers receive SEBI penalty notices for SAR submissions that miss findings, fail to evidence remediation, or use the wrong format. Macksofy ships SARs that hit SEBI's prescribed structure verbatim, with technical evidence attached and a closure trail that addresses the most-asked SEBI inspection questions in advance.

Applicability
  • Trading members / clearing members / depository participants
  • Qualified REs (Type-A / Type-B brokers)
  • Stock brokers under SEBI's enhanced supervision
  • Mutual Fund Distributors (where applicable)
  • Research analysts + Investment advisors above threshold
Standards & frameworks

Aligned to the regulations that matter.

SEBI SAR Format (annexures)
SEBI CSCRF (2024)
SEBI Cybersecurity Circular 2015 (transition mapping)
Stock Exchange / Clearing Corp inspection format
CERT-In empanelment requirement
Methodology

How we run a SEBI SAR engagement.

Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.

  1. 01
    1 · SAR cycle scoping
    • Half-yearly / annual cycle confirmation
    • Auditable controls per SEBI annexures
    • Asset + critical-system inventory
  2. 02
    2 · Audit execution
    • Trading platform + RMS audit
    • Order management + risk management evidence
    • Algo trading + DMA controls (where applicable)
    • Customer-facing portal + KYC pipeline
  3. 03
    3 · Cybersecurity domain
    • VAPT external + internal
    • Phishing / social engineering test (annual)
    • Privileged access + segregation review
    • Data leak + log retention audit
  4. 04
    4 · SAR drafting
    • SEBI prescribed annexure format
    • Severity-graded findings
    • Management responses + closure ETA
    • Auditor opinion + signature
  5. 05
    5 · Submission + closure
    • Submission via member portal
    • Stock Exchange / Clearing Corp queries
    • Closure validation + sign-off
Deliverables

Everything you need to satisfy auditors.

  • SEBI-format System Audit Report (annexure-compliant)
  • Findings register with management response per finding
  • Cybersecurity audit annexure
  • Operational risk audit annexure
  • Auditor opinion letter (CERT-In empanelment cited)
  • Free retest within 30 days · closure letter
Recent engagements
Top-50 Stock Broker (Mumbai)

Half-yearly SAR (first cycle post-CSCRF)

Outcome: Submitted within SEBI deadline; zero SEBI clarification queries returned

At a glance

The shape of a SEBI SAR engagement.

Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.

0
Methodology phases
0
Documented activities
0
Auditor-ready deliverables
0 day
Day retest window
Audit pillars

What we actually examine.

Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.

18CONTROLS MAPPEDacross 6 pillars
Coverage breakdown
  • SAR scope per SEBI circular3 pts
  • IT governance review3 pts
  • Application & infra controls3 pts
  • Change & incident management3 pts
  • BCP / DR3 pts
  • SAR submission pack3 pts
Pillar 01
SAR scope per SEBI circular

We map the SAR exactly to the SEBI circular applicable to your entity class.

  • MII / Stock-Exchange / Depository / DP scope
  • AMC / Broker / RIA / RTA scope
  • Customised system & data inventory
Pillar 02
IT governance review

Where SEBI inspectors usually pull the thread first.

  • IT-strategy + steering-committee evidence
  • Policy currency + board approval trail
  • CISO / CTO charter + reporting lines
Pillar 03
Application & infra controls

The technical-control evidence SEBI SAR submissions hinge on.

  • Trading / DP / RTA application review
  • Network segmentation + DMZ posture
  • Database / endpoint / patch posture
Pillar 04
Change & incident management

The two areas where SEBI most often raises observations.

  • Change-control gating evidence
  • Major-incident root cause + SEBI notice
  • Post-mortem + corrective-action log
Pillar 05
BCP / DR

Live drill evidence, declared RTO / RPO, recovery proof.

  • Cyber-incident DR drill record
  • Site-shift drill + RTO/RPO actuals
  • Alternate-site readiness attestation
Pillar 06
SAR submission pack

Assembled in SEBI's preferred submission format.

  • SAR cover letter + executive summary
  • Control register keyed to SEBI clauses
  • Observation register + remediation tracker
Engagement timeline

From kick-off to regulator-ready report.

The horizontal flow below shows the typical week-by-week shape of a SEBI SAR engagement. Click any station for detail in the methodology section above.

01
Week 1
SAR cycle scoping
02
Week 2
Audit execution
03
Week 3
Cybersecurity domain
04
Week 4
SAR drafting
05
Week 5
Submission + closure
What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Things compliance leads ask before signing.

Half-yearly for Type-A members, annual for Type-B. Specific dates depend on member category and stock exchange.
Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.